High Signal Podcasts Evidence ledger
Method
Browse
← Back to evidence

Evidence receipt / evaluation

Published · transcript-backed

Daniel Miessler: evaluation

1 Jun 2026 The Cognitive Revolution Inside Nathan's Second Brain: Daniel Miessler, Security Expert & Creator of PAI, Audits My AI Setup

“I would say go to the bigger companies and use the ones that are going to be attacked the most and have the most security people working on them because it really is security by obscurity that's protecting the smaller companies.”

— Daniel Miessler

Source trail

Everything needed to verify it.

Speaker
Daniel Miessler
Attribution
Verified speaker
Claim type
evaluation
Recorded
1 Jun 2026
Publisher
The Cognitive Revolution

Transcript context

…High value target, yeah. And and just to be like, I mean, I, I don't even actually want to give the like the full prompt, but you could make a single prompt that just does all this harvesting and builds like perfect spearfishes exactly for you, finds every single vendor. And fortunately, because I'm also talking a lot about I talk about my stack, you talk about your stack. So it's like we literally know the companies to go after. And getting back to the answer to your question, if somebody skilled targets somebody directly, especially now with these good models, most companies, security is not good enough to withstand it, especially if they have any sort of attack surface, if they have employees, if they can be spearfished, it it's, it's fairly, I wouldn't say trivial, but it's fairly easy to, to get into these companies, especially if you have days or weeks or months to keep trying. So I would consider anything that you have in cloud small companies to be eventually compromised, right. So the question is how soon and what do you have in there? And that's why I say limit the number of companies. So I try to use as many Google and Apple things as possible because their security teams are massive and they're just constantly watching this stuff. And if something were to happen, it would happen to a lot of people at the same time and it wouldn't happen to us first. So the signal will come back to us pretty quickly and we could pull back. So screen sharing, password management, I try to use native OS stuff as much as possible and there is now the ability to actually use key chain or to use vaults. Another thing that's really solid is like AWS Vault for storing credentials. So that's another option that you have. I would say go to the bigger companies and use the ones that are going to be attacked the most and have the most security people working on them because it really is security by obscurity that's protecting the smaller companies. So for something like 1, I think it's that's probably good advice. And generally try to stick with the the Titans as as much as possible as well. I don't know that they have maybe they do, but I'm not aware of like a Google or Apple product that would easily allow me to share my API keys with agents, for example. So if you're aware of a solution like you know, please point me to it. But if if there isn't 1, I guess I'm still a little bit confused on the claims that companies like this make because they have the sort of double encryption idea which makes it seem like they're saying that even if one of their employees got hacked. Or even worse, like even if one of their employees went rogue, the idea is supposed to be that somehow, even if I'm a full access 1 password, you know, engineer in good standing, I still wouldn't be able to get Nathan or Daniel's passwords because of something. But it sounds like you basically just don't think that that's really that.…

Stored transcript either side of the excerpt. The highlighted words are the published quote; the surrounding text is unedited source, never generated.

Search evidence